VDB
CVE-2015-3214
CVE-2015-3214
PUBLISHED
The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitrary code on the host OS by triggering use of an invalid index.
EPSS 1.59% · 74.7th percentile
Risk Scores
EPSS Score
1.59%
74.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:14.04:LTS | qemu | 0, 1.5.0+dfsg-3ubuntu5, 1.5.0+dfsg-3ubuntu6 |
Timeline
- Jun 17, 2015 CVE Published
- Aug 27, 2015 PoC Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Oct 28, 2022 EPSS Score
- Dec 20, 2022 EPSS Score
- Feb 3, 2023 EPSS Score
- Feb 13, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 5, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2015-3214 third-party-advisory
- https://www.mail-archive.com/qemu-devel@nongnu.org/msg304063.html third-party-advisory
- https://ubuntu.com/security/notices/USN-2692-1 vendor-advisory
- https://www.cve.org/CVERecord?id=CVE-2015-3214 third-party-advisory